Vulnerability Description
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5g
- https://www.vulncheck.com/advisories/imagemagick-before-26-information-disclosur
FAQ
What is CVE-2026-61862?
CVE-2026-61862 is a vulnerability with a CVSS score of 2.9 (LOW). ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte ...
How severe is CVE-2026-61862?
CVE-2026-61862 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-61862?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.